The required 'shared' check has been red on every run for months — root cause was not CI infrastructure but 14 real HIGH/CRITICAL dependency findings. This bumps kin-openapi (CRITICAL fail-open), golang.org/x/crypto (ssh CVEs), golang.org/x/text, and moby/go-archive to fixed versions. Full suite incl. postgres testcontainers green.
The required 'shared' check has been red on every run for months — root cause was not CI infrastructure but 14 real HIGH/CRITICAL dependency findings. This bumps kin-openapi (CRITICAL fail-open), golang.org/x/crypto (ssh CVEs), golang.org/x/text, and moby/go-archive to fixed versions. Full suite incl. postgres testcontainers green.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Clears the 14 findings (13 HIGH, 1 CRITICAL) that have had the trivy fs
gate in the shared CI job red on every run: kin-openapi 0.138.0 -> 0.144.0
(GHSA-r277-6w6q-xmqw ValidationHandler fail-open + CVE-2026-76905),
x/crypto 0.51.0 -> 0.55.0 (ssh CVE-2026-39828..39835, 42508, 46595,
46597), x/text -> 0.41.0 (CVE-2026-56852), moby/go-archive 0.2.0 -> 0.3.0
(CVE-2026-17106). Full suite incl. postgres harness green; openapi
contract test passes against kin-openapi 0.144.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The required 'shared' check has been red on every run for months — root cause was not CI infrastructure but 14 real HIGH/CRITICAL dependency findings. This bumps kin-openapi (CRITICAL fail-open), golang.org/x/crypto (ssh CVEs), golang.org/x/text, and moby/go-archive to fixed versions. Full suite incl. postgres testcontainers green.
🤖 Generated with Claude Code
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.